Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmfx-4v44-9qw9

Опубликовано: 25 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

Summary

The webhook_url field in the Jobs API silently passes validation when DNS resolution fails (socket.gaierror), enabling DNS rebinding attacks. An attacker's domain can initially resolve to a public IP (passing validation) then switch to an internal IP before the server makes the HTTP request.

Details

The validator catches socket.gaierror and silently allows the URL:

# src/praisonai/praisonai/jobs/models.py:55 try: ip = socket.gethostbyname(hostname) ip_obj = ipaddress.ip_address(ip) if ip_obj.is_private or ip_obj.is_loopback: raise ValueError("private address") except socket.gaierror: pass # BUG: DNS failure silently ignored → SSRF bypass

The HTTP call is made later with no re-validation:

# src/praisonai/praisonai/jobs/executor.py:402 async with httpx.AsyncClient() as client: await client.post(job.webhook_url, ...) # no second IP check

Proof of Concept

DNS rebinding flow:

  1. Register attacker.com with TTL=1s → resolves to 1.2.3.4 (public IP)
  2. Submit job: webhook_url=http://attacker.com/callback
  3. Validation passes (public IP)
  4. Switch DNS: attacker.com127.0.0.1
  5. Job completes → server POSTs to 127.0.0.1 → internal SSRF

Unresolvable domain bypass (no DNS rebinding required):

curl -X POST http://:8005/api/v1/runs \ -d '{"prompt":"run","webhook_url":"http://unresolvable.internal/cb","agent_yaml":"..."}' # Validation: gaierror → pass → URL accepted

Impact

SSRF to internal HTTP services: admin panels, databases, and cloud metadata APIs (e.g., http://169.254.169.254/). Exploitable without authentication.

Пакеты

Наименование

PraisonAI

pip
Затронутые версииВерсия исправления

<= 4.6.48

4.6.58

EPSS

Процентиль: 12%
0.00219
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-367
CWE-918

Связанные уязвимости

CVSS3: 6.8
nvd
22 дня назад

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58.

EPSS

Процентиль: 12%
0.00219
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-367
CWE-918